← Back to CVE List

CVE-2018-18859

Published: 2018-11-20T19:29Z
Last Modified: 2024-11-21T03:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the value of the "tun_path" or "tap_path" pathname in a kextload() call. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt